|
Family: Debian Local Security Checks --> Category: infos
[DSA836] DSA-836-1 cfengine2 Vulnerability Scan
Vulnerability Scan Summary DSA-836-1 cfengine2
Detailed Explanation for this Vulnerability Test
Javier Fernández-Sanguino Peña discovered insecure temporary file use
in cfengine2, a tool for configuring and maintaining networked
machines, that can be exploited by a symlink attack to overwrite
arbitrary files owned by the user executing cfengine, which is
probably root.
The old stable distribution (woody) is not affected by this problem.
For the stable distribution (sarge) these problems have been fixed in
version 2.1.14-1sarge1.
For the unstable distribution (sid) these problems will be fixed soon.
We recommend that you upgrade your cfengine2 package.
Solution : http://www.debian.org/security/2005/dsa-836
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|